Ensure we are in accept state in DTLSv1_listen
authorMatt Caswell <matt@openssl.org>
Wed, 23 Nov 2016 23:03:13 +0000 (23:03 +0000)
committerMatt Caswell <matt@openssl.org>
Tue, 29 Nov 2016 10:01:49 +0000 (10:01 +0000)
Calling SSL_set_accept_state() after DTLSv1_listen() clears the state, so
SSL_accept() no longer works. In 1.0.2 calling DTLSv1_listen() would set
the accept state automatically. We should still do that.

Fixes #1989

Reviewed-by: Andy Polyakov <appro@openssl.org>
ssl/d1_lib.c

index 20970c3f024ef1a5c2e10a85d711f62105d2bccb..c1d160ecd4306997ac41e45534e9bcb87742c8b1 100644 (file)
@@ -432,6 +432,11 @@ int DTLSv1_listen(SSL *s, BIO_ADDR *client)
     BIO_ADDR *tmpclient = NULL;
     PACKET pkt, msgpkt, msgpayload, session, cookiepkt;
 
+    if (s->handshake_func == NULL) {
+        /* Not properly initialized yet */
+        SSL_set_accept_state(s);
+    }
+
     /* Ensure there is no state left over from a previous invocation */
     if (!SSL_clear(s))
         return -1;